Impact
The vulnerability is an Incorrect Authorization flaw (CWE-863) that allows an authenticated user with privileges on one resource to misuse the Elasticsearch Modify Data Streams API and alter a data stream for which they lack proper authorization. By changing the stream configuration or injecting data, the attacker can impact the stream’s indexing and search behavior, but the flaw does not expose the actual contents of the stream.
Affected Systems
Elastic:Elasticsearch products are affected. The grant specifies that any user who can authenticate and has sufficient permissions on a single resource can exploit the flaw via the Modify Data Streams API. Version information specific to the affected releases is not provided in the current data set.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers must be authenticated and possess elevated privileges on at least one resource, which limits the vector but still presents a significant risk if organizational access controls are relaxed. The attacker can alter search behavior and data insertion paths without reading the stream data.
OpenCVE Enrichment